1200KM / tool
Mythic — Attack Tool
Mythic is an open source, cross-platform post-exploitation/command and control platform. Mythic is designed to "plug-n-play" with various agents and communication channels. Deployed Mythic C2 servers have been observed as part of potentially malicious infrastructure.
Tool identity and evidence
Included because the active pinned ATT&CK object has type tool. This is an upstream classification, not an assurance of benignness or a recommendation to run it.
Aliases: Mythic
Existing author guides
No reviewed association in this snapshot.
Primary documentation
No reviewed association in this snapshot.
Connected ecosystem references
Linked tags
Technique-specific simulations and detections
Detection links describe the associated behavior, not independently verified tool-specific signatures.
- T1008 · Fallback Channels · Detection rules & anomalies
- T1030 · Data Transfer Size Limits · Detection rules & anomalies
- T1071.001 · Web Protocols · Detection rules & anomalies
- T1071.002 · File Transfer Protocols · Detection rules & anomalies
- T1071.004 · DNS · Detection rules & anomalies
- T1090.001 · Internal Proxy · Detection rules & anomalies
- T1090.002 · External Proxy · Detection rules & anomalies
- T1090.004 · Domain Fronting · Detection rules & anomalies
- T1095 · Non-Application Layer Protocol · Detection rules & anomalies
- T1119 · Automated Collection · Detection rules & anomalies
- T1132 · Data Encoding · Detection rules & anomalies
- T1572 · Protocol Tunneling · Detection rules & anomalies
- T1573.002 · Asymmetric Cryptography · Detection rules & anomalies
Telemetry context
Derived from the explicitly linked TTPs; not proof of sensor coverage for this tool.
- Application Log Content · DC0038
- Command Execution · DC0064
- File Access · DC0055
- File Creation · DC0039
- Firewall Rule Modification · DC0051
- Module Load · DC0016
- Network Connection Creation · DC0082
- Network Traffic Content · DC0085
- Network Traffic Flow · DC0078
- Process Creation · DC0032
- Script Execution · DC0029
- Service Creation · DC0060
- User Account Authentication · DC0002
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.